WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 13,351–13,400 of 17,733 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Woo Manage Fraud Orders | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.6.1 |
CVE-2024-9937 |
Wordfence | |
| 5.4 Medium | ElementInvader Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.8 |
CVE-2024-9888 |
Wordfence | |
| 5.4 Medium | Community by PeepSo | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 6.4.6.1 |
CVE-2024-9873 |
Wordfence | |
| 6.1 Medium | Kama SpamBlock | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.8.2 |
CVE-2024-9647 |
Wordfence | |
| 6.1 Medium | Locatoraid Store Locator | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.9.47 |
CVE-2024-9652 |
Wordfence | |
| 4.3 Medium | Multiline files upload for contact form 7 | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation |
≤ 2.8.1 |
CVE-2024-9891 |
Wordfence | |
| 4.3 Medium | WP ULike | Cross-Site Request Forgery Cross-Site Request Forgery to Statistic Deletion No login needed |
≤ 4.7.4 |
CVE-2024-9649 |
Wordfence | |
| 5.6 Medium | UltimateAI | Authentication Bypass Limited User Password Change due to Improper Empty and Missing Default Value Check No login needed |
≤ 2.8.3 |
CVE-2024-9104 |
Wordfence | |
| 6.1 Medium | Smart Online Order for Clover | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.5.7 |
CVE-2024-8787 |
Wordfence | |
| 4.7 Medium | Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons | Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed |
≤ 2.6.5 |
CVE-2024-8541 |
Wordfence | |
| 6.4 Medium | SEO Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta |
≤ 1.9 |
CVE-2024-9521 |
Wordfence | |
| 6.4 Medium | Smart Online Order for Clover | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via moo_receipt_link Shortcode |
≤ 1.5.7 |
CVE-2024-9895 |
Wordfence | |
| 5.3 Medium | WooCommerce | Content Injection Unauthenticated HTML Injection No login needed |
≤ 9.0.2 |
CVE-2024-9944 |
Wordfence | |
| 6.5 Medium | WP 2FA with Telegram | Authentication Bypass Two-Factor Authentication Bypass |
≤ 3.0 |
CVE-2024-9820 |
Wordfence | |
| 4.3 Medium | Elementor | Information Disclosure Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function |
≤ 3.24.5 |
CVE-2024-6757 |
Wordfence | |
| 5.3 Medium | WPIDE | Information Disclosure Unauthenticated Full Path Dislcosure No login needed |
≤ 3.4.9 |
CVE-2024-9546 |
Wordfence | |
| 4.3 Medium | Elementor Addon Elements | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections |
≤ 1.13.8 |
CVE-2024-8902 |
Wordfence | |
| 6.4 Medium | TablePress | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 2.4.2 |
CVE-2024-9595 |
Wordfence | |
| 6.4 Medium | Rescue Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.8 |
CVE-2024-9696 |
Wordfence | |
| 5.3 Medium | Stackable – Page Builder Gutenberg Blocks | Content Injection Page Builder Gutenberg Blocks <= 3.13.6 - Unauthenticated CSS Injection No login needed |
≤ 3.13.6 |
CVE-2024-8760 |
Wordfence | |
| 6.4 Medium | Category Icon | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.0 |
CVE-2024-8915 |
Wordfence | |
| 6.4 Medium | Social Sharing (by Danny) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.3.7 |
CVE-2024-9704 |
Wordfence | |
| 4.3 Medium | Order Attachments for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary File Upload |
2.0 – 2.4.1 |
CVE-2024-9756 |
Wordfence | |
| 6.1 Medium | 2D Tag Cloud | Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Parameter No login needed |
≤ 6.0.2 |
CVE-2024-9670 |
Wordfence | |
| 4.4 Medium | ImagePress - Image Gallery | Cross-Site Scripting Image Gallery <= 1.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings |
≤ 1.2.2 |
CVE-2024-9776 |
Wordfence | |
| 6.4 Medium | Mynx Page Builder | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 0.27.8 |
CVE-2024-9656 |
Wordfence | |
| 4.4 Medium | Forms for Mailchimp by Optin Cat | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Form Color Parameters |
≤ 2.5.7 |
CVE-2024-7489 |
Wordfence | |
| 4.3 Medium | ImagePress - Image Gallery | Broken Access Control Image Gallery <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Post Title Update |
≤ 1.2.2 |
CVE-2024-9824 |
Wordfence | |
| 4.3 Medium | Read more By Adam | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Read More Button Deletion |
≤ 1.1.8 |
CVE-2024-9187 |
Wordfence | |
| 4.3 Medium | ImagePress – Image Gallery | Cross-Site Request Forgery Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.2.2 |
CVE-2024-9778 |
Wordfence | |
| 5.4 Medium | Bridge Core | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Demo Import |
≤ 3.3 |
CVE-2024-9860 |
Wordfence | |
| 6.1 Medium | Easy PayPal Gift Certificate | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via wpppgc_plugin_options No login needed |
≤ 1.2.3 |
CVE-2024-9592 |
Wordfence | |
| 6.5 Medium | CM Tooltip Glossary | Cross-Site Scripting Stored Cross-Site Scripting |
≤ 4.3.9 Fixed in 4.3.11 |
CVE-2024-48041 |
Patchstack | |
| 4.7 Medium | ElementsReady Addons for Elementor | Open Redirect No login needed |
≤ 6.4.2 Fixed in 6.4.3 |
CVE-2024-47353 |
Patchstack | |
| 4.3 Medium | ShopLentor | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template |
≤ 2.9.8 |
CVE-2024-9538 |
Wordfence | |
| 4.3 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template |
≤ 5.6.11 |
CVE-2024-8913 |
Wordfence | |
| 6.5 Medium | WordPress Comments Import & Export | Path Traversal Authenticated (Author+) Arbitrary File Read via Directory Traversal |
≤ 2.3.7 |
CVE-2024-7514 |
Wordfence | |
| 6.4 Medium | WP Ultimate Post Grid | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-grid-with-filters Shortcode |
≤ 3.9.3 |
CVE-2024-9051 |
Wordfence | |
| 4.9 Medium | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | Path Traversal Authenticated (Administrator+) Improper Input Validation via iconUpload Function to Arbitrary File Read |
≤ 2.15.2 |
CVE-2024-9507 |
Wordfence | |
| 6.1 Medium | FULL – Cliente | Cross-Site Scripting Cliente <= 3.1.22 - Reflected Cross-Site Scripting No login needed |
≤ 3.1.22 |
CVE-2024-9211 |
Wordfence | |
| 6.1 Medium | Language Switcher | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.7.13 |
CVE-2024-9610 |
Wordfence | |
| 6.1 Medium | Download Plugins and Themes in ZIP from Dashboard | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.9.1 |
CVE-2024-9232 |
Wordfence | |
| 6.1 Medium | PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.5.14 |
CVE-2024-9436 |
Wordfence | |
| 6.1 Medium | Tainacan | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.21.10 |
CVE-2024-9221 |
Wordfence | |
| 6.1 Medium | BlockMeister – Block Pattern Builder | Cross-Site Scripting Block Pattern Builder <= 3.1.10 - Reflected Cross-Site Scripting No login needed |
≤ 3.1.10 |
CVE-2024-9616 |
Wordfence | |
| 6.1 Medium | Increase upload file size & Maximum Execution Time limit | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.0 |
CVE-2024-9611 |
Wordfence | |
| 6.1 Medium | Embed videos and respect privacy | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.2 |
CVE-2024-9346 |
Wordfence | |
| 5.4 Medium | Linkz.ai | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update via AJAX |
≤ 1.1.8 |
CVE-2024-9587 |
Wordfence | |
| 6.5 Medium | Linkz.ai | Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Update No login needed |
≤ 1.1.8 |
CVE-2024-9586 |
Wordfence | |
| 6.4 Medium | Powerpress | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via skipto Shortcode |
≤ 11.9.18 |
CVE-2024-9543 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.